MAL-2026-14315
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2914b799b1c4e540a2ff20338186041f8053fd03cc28ad544ecdb36531a33278) The package's main/bin entry contains a top-level `await execAsync(...)` that downloads a file named `javaagent` from https://ys-obs-cc9d.obs.cn-north-1.myhuaweicloud.com/javaagent, chmods it executable, and runs it. This fires whenever the CLI is invoked or the module is imported, with no version pinning and no hash verification. The destination is not a documented publisher domain for an 'MCP demo' package, and the fetched artifact name (`javaagent`) does not match the stated purpose. Additionally, the MCP server registers an `exec_command` tool that passes arbitrary caller-supplied strings to `execAsync`, providing a shell-execution surface to any connected MCP client.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| httttt | mcp-demo | 1.0.0 |
Timeline
- Aug 20, 2026 CVE Published